1. Home
  2. IAPP
  3. CIPM Exam

CIPM Certified Information Privacy Manager (CIPM) Exam Topics and Questions

Let's Practice Free IAPP CIPM Questions Aligned with Official Exam Topics

Follows IAPP's official outline Updated 14 Sep, 2026 6 Topics
Reviewed by Ethan King, IAPP CIPM Certified Professional
Topic Content

This topic establishes the foundational architecture of a privacy programme. You need to know how to translate legal and regulatory requirements into an operational structure, how to position privacy within the organisation's risk and compliance landscape, and where the common design failures occur. The exam tests whether you can identify the right sequence of decisions and spot when a framework will collapse under its own contradictions. Candidates who treat this as a policy-writing exercise rather than a structural design challenge...

See More

The question below turns on recognising which framework element must be in place before others can function.

Sample Questions for Topic 1 : Privacy Program: Developing a Framework
Q1

SCENARIO

Please use the following to answer the next QUESTIO N:

For 15 years, Albert has worked at Treasure Box -- a mail order company in the United States (U.S.) that used to sell decorative candles around the world, but has recently decided to limit its shipments to customers in the 48 contiguous states. Despite his years of experience, Albert is often overlooked for managerial positions. His frustration about not being promoted, coupled with his recent interest in issues of privacy protection, have motivated Albert to be an agent of positive change.

He will soon interview for a newly advertised position, and during the interview, Albert plans on making executives aware of lapses in the company's privacy program. He feels certain he will be rewarded with a promotion for preventing negative consequences resulting from the company's outdated policies and procedures.

For example, Albert has learned about the AICPA (American Institute of Certified Public Accountans)/CICA (Canadian Institute of Chartered Accountants) Privacy Maturity Model (PMM). Albert thinks the model is a useful way to measure Treasure Box's ability to protect personal dat

a. Albert has noticed that Treasure Box fails to meet the requirements of the highest level of maturity of this model; at his interview, Albert will pledge to assist the company with meeting this level in order to provide customers with the most rigorous security available.

Albert does want to show a positive outlook during his interview. He intends to praise the company's commitment to the security of customer and employee personal data against external threats. However, Albert worries about the high turnover rate within the company, particularly in the area of direct phone marketing. He sees many unfamiliar faces every day who are hired to do the marketing, and he often hears complaints in the lunch room regarding long hours and low pay, as well as what seems to be flagrant disregard for company procedures.

In addition, Treasure Box has had two recent security incidents. The company has responded to the incidents with internal audits and updates to security safeguards. However, profits still seem to be affected and anecdotal evidence indicates that many people still harbor mistrust. Albert wants to help the company recover. He knows there is at least one incident the public in unaware of, although Albert does not know the details. He believes the company's insistence on keeping the incident a secret could be a further detriment to its reputation. One further way that Albert wants to help Treasure Box regain its stature is by creating a toll-free number for customers, as well as a more efficient procedure for responding to customer concerns by postal mail.

In addition to his suggestions for improvement, Albert believes that his knowledge of the company's recent business maneuvers will also impress the interviewers. For example, Albert is aware of the company's intention to acquire a medical supply company in the coming weeks.

With his forward thinking, Albert hopes to convince the managers who will be interviewing him that he is right for the job.

In consideration of the company's new initiatives, which of the following laws and regulations would be most

appropriate for Albert to mention at the interview as a priority concern for the privacy team?

Topic Content

Once the framework exists, governance determines who makes decisions, who is accountable when things go wrong, and how the programme maintains authority across the organisation. This topic covers the allocation of roles and responsibilities, the structures that enforce them, and the mechanisms that prevent governance from becoming ceremonial. You need to understand how to build reporting lines that surface risk before it becomes a breach, how to assign accountability in a way that survives reorganisation, and where governance models fail...

See More

The question that follows tests whether you can identify the governance gap that allows risk to go unreported.

Sample Questions for Topic 2 : Privacy Program: Establishing Program Governance
Q2

The purpose of a data flow map is to help an organization do all of the following EXCEPT?

Topic Content

Assessment is where the programme moves from structure to execution. This topic covers how to inventory data, classify it by risk, map its flows, and identify where processing exceeds legal or policy boundaries. You need to know how to scope an assessment so it captures the right detail without stalling under its own weight, how to prioritise when you cannot assess everything at once, and where assessment processes break down in practice. The exam tests whether you can distinguish between...

See More

The sample below asks you to identify which assessment step must come first in a scenario where data flows are not yet documented.

Topic Content

Protection translates assessment findings into controls. This topic covers the selection, implementation, and maintenance of technical and organisational measures that reduce the risk of unauthorised access, loss, or misuse. You need to know how to match controls to the sensitivity of the data and the threat environment, how to ensure controls remain effective as systems and risks evolve, and where protection strategies fail because they are too rigid or too complex to sustain. The exam tests whether you can identify...

See More

The question below presents a scenario where existing controls have failed, and you must identify which layer of protection was missing.

Topic Content

Sustaining performance is about keeping the programme effective as the organisation changes. This topic covers how to monitor compliance, measure outcomes, maintain stakeholder engagement, and adapt the programme when new risks or requirements emerge. You need to know which metrics reveal genuine performance and which are vanity indicators, how to design reviews that surface problems before they become breaches, and where programmes decay because oversight becomes routine rather than rigorous. The exam tests whether you can distinguish between monitoring that...

See More

The sample question asks you to identify which performance indicator reveals a gap that other metrics are missing.

Topic Content

Response is where the programme is tested under pressure. This topic covers how to handle data subject requests, how to manage breaches and near-misses, and how to ensure the organisation learns from incidents rather than simply surviving them. You need to know how to triage requests and incidents by urgency and impact, how to coordinate across legal, technical, and communications teams, and where response plans fail because they were never exercised or because they assume resources that are not available...

See More

The question below asks you to determine which step in an incident response has been skipped, causing the response to stall.

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full CIPM Exam Questions 🚀
Exams Made Simple. Success Made Possible.